CVE-2014-4264
published 2014-07-17CVE-2014-4264: Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect availability via unknown vectors related to Security.
medium5CVSS 3.1
AVNACLAuNCNINAP
Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect availability via unknown vectors related to Security.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvd5.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.3CRITICAL
Ubuntu
OpenJDK 7 update
vendor_ubuntu·2014-09-17·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK 7 update
Title: OpenJDK 7 update
Summary: This update provides stability updates for OpenJDK 7.
USN-2319-1 fixed vulnerabilities in OpenJDK 7. This update provides
stability fixes for the arm64 and ppc64el architectures.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Ubuntu
OpenJDK 7 regression
vendor_ubuntu·2014-08-26·CVSS 9.3
[CRITICAL] OpenJDK 7 regression
Title: OpenJDK 7 regression
Summary: USN-2319-1 introduced a regression in OpenJDK 7.
USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and d
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-08-20·CVSS 9.3
CVE-2014-2483 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
A vulnerability was discovered in t
Red Hat
OpenJDK: Incorrect TLS/EC management (Security, 8031340)
vendor_redhat·2014-07-15·CVSS 5.0
CVE-2014-4264 [MEDIUM] OpenJDK: Incorrect TLS/EC management (Security, 8031340)
OpenJDK: Incorrect TLS/EC management (Security, 8031340)
Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect availability via unknown vectors related to Security.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.7.0-open
GHSA
GHSA-c8jv-jvr4-6p8c: Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect availability via unknown vectors related to Security
ghsa_unreviewed·2022-05-13
CVE-2014-4264 [MEDIUM] GHSA-c8jv-jvr4-6p8c: Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect availability via unknown vectors related to Security
Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect availability via unknown vectors related to Security.
OSV
openjdk-7 update
osv·2014-09-17·CVSS 9.3
CVE-2014-2483 [CRITICAL] openjdk-7 update
openjdk-7 update
USN-2319-1 fixed vulnerabilities in OpenJDK 7. This update provides
stability fixes for the arm64 and ppc64el architectures.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
OSV
openjdk-7 regression
osv·2014-08-26·CVSS 9.3
[CRITICAL] openjdk-7 regression
openjdk-7 regression
USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive
OSV
openjdk-7 vulnerabilities
osv·2014-08-20·CVSS 9.3
CVE-2014-2483 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)
Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=140852886808946&w=2http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/60326http://secunia.com/advisories/60485http://secunia.com/advisories/60812http://secunia.com/advisories/60890http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www.debian.org/security/2014/dsa-2987http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68612http://www.securitytracker.com/id/1030577http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://access.redhat.com/errata/RHSA-2014:0902https://exchange.xforce.ibmcloud.com/vulnerabilities/94603https://kc.mcafee.com/corporate/index?page=content&id=SB10083http://marc.info/?l=bugtraq&m=140852886808946&w=2http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/60326http://secunia.com/advisories/60485http://secunia.com/advisories/60812http://secunia.com/advisories/60890http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www.debian.org/security/2014/dsa-2987http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/68612http://www.securitytracker.com/id/1030577http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://access.redhat.com/errata/RHSA-2014:0902https://exchange.xforce.ibmcloud.com/vulnerabilities/94603https://kc.mcafee.com/corporate/index?page=content&id=SB10083
2014-07-17
Published